The package includes tests, a substantial README, a GitHub release, and no install-time scripts. Its last release and repository push were about three years ago, and the declared CC-BY-3.0 license conflicts with the detected CC0-1.0 file.
55%
Total Score
50
100
79
100
A license file is present, but the manifest declares CC-BY-3.0 while the detected file says CC0-1.0. The mismatch creates legal ambiguity despite the package being licensed.
The package has 17 releases since 2017, but none in the last 12 months and its latest release was about three years ago, indicating prolonged inactivity.
The repository recorded no commits and no active maintainers in the last three months; together with the old latest release, this points to stalled maintenance.
Composer build tooling is present, but no security scanning tools were detected. This is a minor transparency gap, partly outweighed by the package's tests and established repository.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.2 || ^6.0 | — | — |
hassankhan/config Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.